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AMENDMENTS TO THE CLAIMS 

1-18. (Canceled) 



1 9. (Currently amended) A method for securing data communication between a client in 
an internal network and a server in an external network by way of a an annhcatinn-W.. o^, 
proxy server in the internal network, the method comprising: 

performing, at the proxy server, a network address translation upon a stream of packets 
originating from the client^erein the network add,,.,, is vafhmttA nt . ^ 

Level : 

filtering, at the proxy server, the stream of packets, saeMh* wherein the filtering is 
transparent to the client and wherein r ^ mr4 at a stipj)m and 

transmitting, at the proxy server, the packets to the server after the packets are filtered. 

20. (Currently amended) The method of claim 19, further comprising: 
filtering, at the proxy server, a second slream of packets originating from the server in the 
external network „„w herein the fi l terin g is transparent to th, rlie nt and wh^n ^ ■„ 
Performed «t a stream wi. ' 

Panning, at the proxy saver, a rev** network address translation npon the packets in 
tt^ond stream, ^ , n , ^ „^, nr|r M< 1 1 h ^ 

m«red.' ra ° SmiBin8 ' " ** *" ^ " *• ""■ < st »™ <he packets are 

21. (Currents amended) A computer-readabfe medium having instructions stored 



forminp;, at the provy 



IgtWQrk address tr^l**™ „ r ~ n n nf p aplfgfp 
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Originating from the client, wherein the netwnrfc fl d d res3 translate i, performed at » 
levej; 

filtering, at the proxy iwrrn , the stream of p«ck^ wherein tn, fii^ ng ^ ^ trt 
the client, and wherein the filtering is nerfnrm ed at a stream 1^; p^j 

transmitting, at the proxy serv er, the pa c kets t o the server „tw th e packets ^ fii^ 

22. (Currently amended) A system for securing data communication across an external 
computer network, comprising: 

a client located in an internal computer network; 

a server located in the external computer network and in communication with the client; 

and 

a auarolication-levd patnva y proxy device located in the internal computer network and 
comprising components for (1) performing, at a packet level a network address translation upon 
a stream of packets originating from the client and (2) filterin g, at a stream level, the stream of 
packets and transmitting the packets to the server, wherein sueMh* the filtering is transparent to 
the client. 

23. (Currently amended) The system of claim 22, wherein the components of the proxy 

device comprise; 

a first component for filtering said stream of packets, and also & filtering.atajtoaffl 
leypl and transp arentl y to t he rlirnt, a second stream of packets originating from the server; and 

a second component for performing said network address translation, and also for 
performin g, at a packet level , a reverse network address translation «pe* with respect m the 
packets m the second sfream and transmitting the packets in the second stream to the client. 

24. (Currently amended) A An annlication-l^, ^ ^ device , ocated m ^ 
internal network, comprising: 

^^^otnponent for performing^ a packet level, anetwork address translation 
Ww.tlu^ectto a stream of packets originating from a client in the internal network, where 
Stem the client is communicating the stream of packets to a server located in an external 
network; 
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«**hh» a component for filtering, at a stream level, the stream of packet s, wherein 
that the filtering is transparent to the client; and 

a component for transmitting the packets to the server after the packets are 

filtered. 

25. (Currently amended) The proxy device of claim 24, further comprising: 

a component for filtering, at a stream lev.l „ n A t, a ™ rrentlv to the diftt1t a 
second stream of packets originating from the server; 

***** a^fionsnt for perfonnine. at a t^ke* a reverse network address 
translation upon the packets in the second stream; and 

a^om^nent for transmitting the packets in the second stream to the client. 

26. (New) The computer-readable medium of claim 21, wherein the method further 

comprises: 

filtering, at the proxy server, a second stream of packets originating from the server in the 
external network, wherein the filtering is transparent to the client, and wherein the filtering is 
performed at a stream level; 

performing, at the proxy server, a reverse network address translation upon the packets in 
the second stream, wherein the reverse network address translation is performed at a packet 
level; and 

transmitting, at the proxy server, the packets in the second stream after the packets are 

filtered. 
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